 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1" }; O7 _) \% _, r
Scan saved at 16:55:24, on 2006-5-68 z$ O) Y6 T9 t
Platform: Windows XP SP2 (WinNT 5.01.2600)3 z. }, u1 ]8 o2 q2 r s& n
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
3 V0 p" n" B! O9 W6 ?: o- P5 v7 H+ A7 r1 p0 }+ }
Running processes:
, O& I4 a9 _2 g- s: M7 K' kC:\WINDOWS\System32\smss.exe
- \" Q; m0 Y8 ?2 Z% x% v: PC:\WINDOWS\system32\winlogon.exe
3 Z$ W. O7 e5 U- x( r4 [C:\WINDOWS\system32\services.exe
2 T! G N2 v' S1 Y' Q/ u, GC:\WINDOWS\system32\lsass.exe
% w. l$ r0 W, t4 s; \5 y- EC:\Program Files\Common Files\Virtual Token\vtserver.exe
l$ f+ J: L. t) P$ l5 B/ N+ DC:\WINDOWS\system32\ibmpmsvc.exe
$ D t9 S; p* h% ^8 z6 z. M8 ^C:\WINDOWS\system32\svchost.exe
2 v& ~! W. Z2 N3 Q% a" kC:\WINDOWS\System32\svchost.exe& f1 |1 x8 a1 O5 e9 B( _
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe; B$ @' s+ x p# z! _2 A1 x
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe" k/ Z3 J& \+ F& s
C:\WINDOWS\system32\spoolsv.exe3 T5 K4 P, [ u8 b
C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
9 y( r$ S% \5 d: rC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe7 R4 ]; X* i: T+ `8 h$ U5 j
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
! R3 L( Y/ D' c% s, xC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE: y' W8 G; \ ]& [
C:\Program Files\F-Secure\Common\FSMA32.EXE
5 c/ ], V7 N, d. e) oC:\Program Files\F-Secure\Common\FSMB32.EXE# k6 e% w( ?& n+ h7 R
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
l* Y; g5 E3 ?9 E+ P" pC:\Program Files\F-Secure\Anti-Virus\fssm32.exe
@8 x: [: n( E, J8 w4 v( lC:\WINDOWS\System32\QCONSVC.EXE
0 c. ]) i8 O* I! x0 `4 A+ l( RC:\Program Files\F-Secure\Common\FCH32.EXE
3 P4 V" u2 X1 @7 hC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe" I: }* ] Y D
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
! B, T s' A' JC:\WINDOWS\System32\TPHDEXLG.EXE
4 }3 J3 g5 q4 g, b Q' QC:\Program Files\F-Secure\Common\FAMEH32.EXE
, D t# q! [6 n' ^4 z" | {3 OC:\WINDOWS\system32\TpKmpSVC.exe
4 X8 M) Z' v$ h5 Z% m$ O5 j- FC:\Program Files\F-Secure\Anti-Virus\fsqh.exe2 c$ A$ H. o7 i* `% w" S; {1 _
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
2 w& e+ f+ k( mC:\Program Files\F-Secure\Common\FNRB32.EXE$ o' D6 Z8 n/ {0 D6 ~
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
1 a* V% c8 l$ C8 E) @7 b* mC:\Program Files\F-Secure\Common\FIH32.EXE
0 v/ `8 G$ ^* ]C:\Program Files\F-Secure\Anti-Virus\fsav32.exe2 W/ k0 w8 L3 G9 x. ]
C:\WINDOWS\Explorer.EXE
; d; F1 M% G5 U2 [; tC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
- l4 s9 P& E8 |C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
( j. L' W& E: M$ e/ S# B; PC:\WINDOWS\system32\hkcmd.exe
% k$ C# I; d/ ^. d2 ^ NC:\WINDOWS\system32\TpShocks.exe
# Q! h- U+ w. f9 n% k% xC:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
+ t+ j( W! _3 c+ g) u0 rC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe5 S9 N( b) g0 r, S" L0 ]
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe9 C& s4 s( d# ?4 @
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe: o0 k; Z% v& ?4 u3 `! ~( ^
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
( u1 o7 @6 d" |! I. BC:\WINDOWS\system32\dla\tfswctrl.exe
- i3 J9 e) B0 k& W5 `C:\Program Files\IBM\Messages By IBM\ibmmessages.exe0 s+ l5 y Y6 |2 a- ?
C:\IBMTOOLS\UTILS\ibmprc.exe
4 s/ `% d: y, r G! q4 v5 s* xC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
* H, p! i7 }/ m' W8 k2 f" d' mC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
% v; Q/ V g; ?7 n, H- _+ mC:\WINDOWS\System32\svchost.exe
+ K2 T, Y# x7 f7 p0 \$ o+ n6 mC:\WINDOWS\system32\rundll32.exe
6 n, F- D2 p+ E' E) t8 O/ ]C:\Program Files\F-Secure\Common\FSM32.EXE
3 M t% K6 J. D& y! z. SC:\WINDOWS\system32\CTFMON.EXE* Z* B. W3 ~2 R" {
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe$ g3 K' F0 R" j7 N; \
C:\Program Files\Digital Line Detect\DLG.exe- C9 T" ^- F$ y0 x$ H1 l
C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
& N* M3 t! z* p8 _1 d3 D0 h dC:\Program Files\F-Secure\FSGUI\fsguidll.exe
z. D! Y M- O s _C:\Program Files\Messenger\msmsgs.exe& q( W9 ^- p! H/ b7 y: x1 K5 Z
C:\Program Files\Internet Explorer\iexplore.exe4 q* U7 K$ A5 r9 t9 W
C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
4 t' \7 ~: I6 y! T# \/ p6 P0 K* X
- a/ E- y# e M# a0 S( Q2 vO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
6 g8 p4 N. [9 N4 X. BO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
g* j! @9 T0 S+ r: j8 V5 } p) XO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
& ]- l; j, T0 f- r6 G& L+ ]O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe* N) e8 N* w: f
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe d" g# G. e- t5 E, V
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
3 P8 \: y2 ~/ M+ G: R5 `O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
% X8 o" d$ B- M. E# ^O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
9 k9 Y0 I4 r" m! y! zO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup: @. ?5 a( q6 T1 ?7 \1 E
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
" E: U3 \; D: v; kO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
2 G9 D& [1 K* ]4 oO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
4 l& x! V' S* _2 b# fO4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray# N% p* u g' s. i" q; g
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r0 t# V! Z# b& P; m$ X
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
6 g: M3 f& {; \( NO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe1 q$ c! \9 B( p
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe5 i) F9 j5 m2 s" P7 E( @
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE- ^# V* D* O1 ~; B8 i
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
8 B1 L" q4 D! K* A0 u; ?" LO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
8 q$ {7 m: `" U$ U; qO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
( y" Z& x" I$ C3 R/ m( U, G1 eO4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32/ w4 B: o) ^: ^: A U0 t
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
2 L# C7 ?2 x( u; O8 z. j9 W5 ?O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
8 ~2 M5 g3 L- t% u! p& eO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC/ l( n7 a0 g7 {' c3 D+ V' O
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
# m: v+ v1 ?: B aO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
+ |' }) [2 i7 g7 x+ \4 eO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
( R$ n8 T3 S8 W2 wO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
6 L) W$ Y6 A( @% ?" R3 j: eO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe* s, w5 ?! S, R2 t
O4 - Global Startup: Digital Line Detect.lnk = ?
. f4 i' ~1 r7 a# b! K2 _& zO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
, D2 C1 m% N1 E5 A; R% CO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
0 K" L) T4 \9 \; N2 P* vO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
6 i6 w- C- f# P& ]( t1 I& h3 ^7 jO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
) \. x" D/ L+ Q' j/ v7 F1 \O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
% E( Y5 H# I% B& P" M, |" M; ^O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll% W9 k/ I* ]+ N
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
8 n) r4 j" B ]' i. R1 h) m4 b) FO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe' ]5 U* W. z3 D' j5 l0 v1 s0 n
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe1 D8 B" ]. j0 ^' W, l' y0 l
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
. q: n4 F$ A8 |; w+ GO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll! d8 Z! V+ G( T2 G
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll4 y2 H* { D0 v9 }7 f1 [% I( p4 m( T
O11 - Options group: [JAVA_IBM] Java (IBM)8 x5 D: ?. S" @' s& e) X/ I8 Z
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
& B; v5 V: b7 G7 n8 p4 LO20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll* Z8 l" \6 j$ [: }( }
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll: I" V' n- H2 d M7 o: x
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
+ s% \! U9 h9 r0 \3 j; _0 E1 pO23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
" v7 C0 i/ S! Z0 s$ ]7 I5 m; jO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe0 e) Q, m, g% B, {3 O
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe6 G; s. _7 L$ H3 J# n0 U) c
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
$ T) }( t+ ~$ j; B2 G2 \O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe! Q9 E! V. a. N
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
: |1 W( ` A# d/ E, q! ^O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
% ~; ?% J) U0 h- P4 u" wO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe# @/ F& W$ t2 A. P3 [
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe! ~' V I2 v9 v* ?4 g: l
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
0 r( B' W, B' L5 eO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
. E3 x ]6 i$ x; G) }, J( z9 t2 ]O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
& U2 K0 Y r; f! yO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe# |8 q I$ c7 e# Q# t6 H
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
4 b" F* G( O7 @. a- Q) b4 g- kO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
r2 c" a0 D( w p& MO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE: g# ~4 a& u6 Q. s2 l& X
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
0 |/ X1 `# @ L: ~O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|